Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
99 results
hackguard preview

hackguard

GitHubmachine1337/hackguard

FAST WEB APPLICATION VULNERABILITY SCANNER written in python3

information-gatheringmisconfigurationpenetration-testing+3
30
3 years ago
CVE-2025-30208 preview

CVE-2025-30208

GitHubxuemian168/cve-2025-30208

全网首发 CVE-2025-31125 CVE-2025-30208 CVE-2025-32395 Vite Scanner

exploitationinformation-gatheringreconnaissance+3
471 year ago
Hscan preview

Hscan

GitHubjas502n/hscan

Hscan-Win-Gui

database-securityinformation-gatheringnetwork-mapping+5
168 years ago
CVE-2026-64638-POC preview

CVE-2026-64638-POC

GitHubimbas007/cve-2026-64638-poc

CVE-2026-64638: WordPress Pre-auth XSS → RCE (XSS2Shell) PoC

exploitationinformation-gatheringpayload-generation+4
613 days ago
GETROBARB preview

GETROBARB

GitHubhackingteamoficial/getrobarb

Automated reconnaissance and XSS detection framework integrating subfinder, httpx, katana, gospider, waybackurls, and dalfox into a 9-stage pipeline…

crawlerdns-analysisinformation-gathering+7
94 months ago
CVE-2022-3590-WordPress-Vulnerability-Scanner preview

CVE-2022-3590-WordPress-Vulnerability-Scanner

GitHubhxlxmj/cve-2022-3590-wordpress-vulnerability-scanner

This repository contains a Python script that checks WordPress websites for the CVE-2022-3590 vulnerability, which exploits an unauthenticated blind…

exploitationinformation-gatheringpenetration-testing+3
73 years ago
CVE-2022-35499 preview

CVE-2022-35499

GitHubpn-tester/cve-2022-35499

Proof-of-concept exploit for reflected cross-site scripting (XSS) vulnerability in Trimble TM4WEB <=22.2.0, demonstrating injection via arbitrary URL…

exploitationinformation-gatheringpenetration-testing+3
1 month ago
wp2shell preview

wp2shell

GitHubkulichr/wp2shell

Non-intrusive checker for CVE-2026-63030 / CVE-2026-60137 ("wp2shell"), a pre-authentication RCE chain in WordPress core.

exploitationinformation-gatheringreconnaissance+3
1 month ago
CVE-2025-68461 preview

CVE-2025-68461

GitHubgotr00t0day/cve-2025-68461

A C++ security scanner tool to detect Cross-Site Scripting (XSS) vulnerabilities in Roundcube Webmail installations.

information-gatheringpenetration-testingreconnaissance+3
78 months ago
CVE-2026-48908-by-yora preview

CVE-2026-48908-by-yora

GitHubyora1928/cve-2026-48908-by-yora

Passive security checker for CVE-2026-48908 affecting SP Page Builder.

exploitationinformation-gatheringpayload-generation+7
28 days ago
CVE-2024-9047-PoC preview

CVE-2024-9047-PoC

GitHubisee857/cve-2024-9047-poc

WordPress File Upload插件任意文件读取漏洞(CVE-2024-9047)批量检测脚本

exploitationinformation-gatheringpenetration-testing+3
51 year ago
WSS preview

WSS

GitHubnu11secur1ty/wss
code-analysisinformation-gatheringpassword-attacks+3
31 month ago
PressVector preview

PressVector

GitHubvulnquest58/pressvector

PressVector - Advanced WordPress Vulnerability Scanner CVE-2026-63030 (REST batch route confusion) / CVE-2026-60137 (SQLi) Developer: Vulnquest

information-gatheringpenetration-testingreconnaissance+3
129 days ago
log4jcheck preview

log4jcheck

GitHubolafhaalstra/log4jcheck

Check list of URLs against Log4j vulnerability CVE-2021-44228

exploitationinformation-gatheringpenetration-testing+3
54 years ago
CVE-2025-24813-Scanner preview

CVE-2025-24813-Scanner

GitHubmattb709/cve-2025-24813-scanner

CVE-2025-24813-Scanner is a Python-based vulnerability scanner that detects Apache Tomcat servers vulnerable to CVE-2025-24813, an arbitrary file…

exploitationinformation-gatheringpenetration-testing+3
51 year ago
CVE-2025-29927 preview

CVE-2025-29927

GitHub0xwhoknows/cve-2025-29927

Async Python scanner for Next.js CVE-2025-29927. Uses aiohttp & aiofiles to efficiently process large URL lists, detect vulnerabilities, and save…

exploitationinformation-gatheringpenetration-testing+3
31 year ago
CVE-2025-31324 preview

CVE-2025-31324

GitHubrxerium/cve-2025-31324

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially…

exploitationinformation-gatheringpenetration-testing+3
410 months ago
CVE-2026-9082 preview

CVE-2026-9082

GitHubstrobelpierre/cve-2026-9082

Semi-passive scanner that detects Drupal installations vulnerable to CVE-2026-9082 (PostgreSQL SQL injection) via fingerprinting, version detection,…

database-securityinformation-gatheringreconnaissance+3
2 months ago
Previous123456Next